We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2023-52997

ipv4: prevent potential spectre v1 gadget in ip_metrics_convert()



Description

In the Linux kernel, the following vulnerability has been resolved: ipv4: prevent potential spectre v1 gadget in ip_metrics_convert() if (!type) continue; if (type > RTAX_MAX) return -EINVAL; ... metrics[type - 1] = val; @type being used as an array index, we need to prevent cpu speculation or risk leaking kernel memory content.

Reserved 2025-03-27 | Published 2025-03-27 | Updated 2025-05-04 | Assigner Linux

Product status

Default status
unaffected

6cf9dfd3bd62edfff69f11c0f111bc261166e4c7 before ef050cf5fb70d995a0d03244e25179b7c66a924a
affected

6cf9dfd3bd62edfff69f11c0f111bc261166e4c7 before 746db9ec1e672eee13965625ddac0d97e16fa20c
affected

6cf9dfd3bd62edfff69f11c0f111bc261166e4c7 before 34c6142f0df9cd75cba5a7aa9df0960d2854b415
affected

6cf9dfd3bd62edfff69f11c0f111bc261166e4c7 before d50e7348b44f1e046121ff5be01b7fb6978a1149
affected

6cf9dfd3bd62edfff69f11c0f111bc261166e4c7 before 6850fe301d015a7d2012d1de8caf43dafb7cc2f6
affected

6cf9dfd3bd62edfff69f11c0f111bc261166e4c7 before 1d1d63b612801b3f0a39b7d4467cad0abd60e5c8
affected

Default status
affected

4.3
affected

Any version before 4.3
unaffected

4.19.272
unaffected

5.4.231
unaffected

5.10.166
unaffected

5.15.91
unaffected

6.1.9
unaffected

6.2
unaffected

References

git.kernel.org/...c/ef050cf5fb70d995a0d03244e25179b7c66a924a

git.kernel.org/...c/746db9ec1e672eee13965625ddac0d97e16fa20c

git.kernel.org/...c/34c6142f0df9cd75cba5a7aa9df0960d2854b415

git.kernel.org/...c/d50e7348b44f1e046121ff5be01b7fb6978a1149

git.kernel.org/...c/6850fe301d015a7d2012d1de8caf43dafb7cc2f6

git.kernel.org/...c/1d1d63b612801b3f0a39b7d4467cad0abd60e5c8

cve.org (CVE-2023-52997)

nvd.nist.gov (CVE-2023-52997)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2023-52997

Support options

Helpdesk Chat, Email, Knowledgebase